Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

cvat — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in cvat, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting CVAT, a cloud-based computer vision annotation tool. It collects data on software flaws such as cross-site scripting, path traversal, and insecure permissions within the platform. The dataset spans advisories published from 2020 through the present, capturing both critical and moderate severity issues identified by researchers and developers. Readers can utilize this resource to monitor the security posture of the CVAT project, understand common weakness patterns in open-source annotation tools, and review the historical context of specific bug types. This aggregation helps users assess risk when deploying the software in production environments or when integrating it into larger machine learning pipelines. By consolidating scattered security reports into a single view, the page provides a comprehensive overview of the product’s reliability and the responsiveness of its maintainers to reported issues. It serves as a technical reference for security professionals and developers who need to verify patching status or evaluate the overall stability of the codebase over time.

Vendor: cvat-ai

CVE ID Title CVSS Severity Published
CVE-2026-73220 CVAT: Stored XSS via annotation guides in audio tasks CWE-80 8.5 High 2026-08-20
CVE-2026-73221 CVAT: Flawed authorization logic in endpoints related to lambda requests CWE-863 5.3 Medium 2026-08-11
CVE-2026-73219 CVAT: Denial of service with regards to automatic annotation CWE-1288 5.3 Medium 2026-08-11
CVE-2026-65986 CVAT has stored XSS via annotation guide assets CWE-79 8.5 High 2026-08-04
CVE-2026-47682 CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes CWE-22 7.1 High 2026-08-04
CVE-2026-58373 CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence CWE-862 4.3 Medium 2026-06-30
CVE-2026-44369 CVAT: Stored XSS via annotation guides CWE-80 - - 2026-05-13
CVE-2026-23526 CVAT vulnerable to privilege escalation of users with staff status CWE-267 6.5AI Medium AI 2026-01-21
CVE-2026-23516 CVAT vulnerable to XSS via skeleton SVG images CWE-83 6.5AI Medium AI 2026-01-21
CVE-2025-68430 CVAT vulnerable to directory traversal via mounted share listing CWE-24 4.3AI Medium AI 2025-12-19
CVE-2025-64485 CVAT: Mounted share file overwrite via crafted request CWE-22 7.1 - 2025-11-07
CVE-2025-54573 CVAT vulnerable to email verification bypass by use of basic authentication CWE-287 4.3 Medium 2025-07-30
CVE-2025-49135 CVAT missing validation for in-progress backup upload names CWE-639 6.5AI Medium AI 2025-06-25
CVE-2025-48381 CVAT has information disclosure via browsable API CWE-201 4.3AI Medium AI 2025-05-30
CVE-2025-23045 CVAT allows remote code execution via tracker Nuclio functions CWE-502 8.8 - 2025-01-28
CVE-2024-47172 Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints CWE-863 5.4 Medium 2024-09-30
CVE-2024-47064 Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints CWE-79 6.5 - 2024-09-30
CVE-2024-47063 Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint CWE-79 6.5 - 2024-09-30
CVE-2024-45393 Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries CWE-862 6.4 Medium 2024-09-10
CVE-2024-37306 CVAT's export and backup-related API endpoints are susceptible to CSRF CWE-352 7.1 High 2024-06-13
CVE-2024-37164 CVAT SSRF via custom cloud storage endpoints CWE-918 7.1 High 2024-06-13
CVE-2022-31188 Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT) CWE-918 8.6 High 2022-08-01

All 22 known CVE vulnerabilities affecting cvat with full Chinese analysis, references, and POCs where available.